Stickybooks

Security

Last updated September 17, 2026

A summary of how we protect your account and your data. This is a plain-language overview, not a substitute for our Privacy Policy.

Encryption

All traffic to and from Stickybooks is encrypted (HTTPS), enforced on every request. Your password is never stored — only a one-way hash. POS integration credentials you connect are encrypted at rest, separately from the rest of your data.

Account protection

Passwords must be at least 12 characters with a mix of upper and lowercase letters. Sessions automatically sign out after 30 minutes of inactivity. Sign-in attempts are rate-limited to block automated password-guessing, and we keep a record of sign-in activity so unusual access can be investigated.

Data isolation

Every organization's purchase orders, inventory, and sales data is scoped to that organization. Ordinary staff accounts can't see or reach another company's data. Access beyond that boundary is limited to a small number of Stickybooks staff who support customer accounts directly.

Backups

Your data is backed up nightly and stored off our production servers, with backups kept for 30 days. Restore procedures are tested regularly, not just written down and forgotten.

Monitoring

We monitor the application for errors and unusual activity, and keep logs of authentication events. This lets us catch and respond to problems quickly rather than finding out from you.

Reporting a concern

If you believe you've found a security issue, reach out and describe what you found. We take these reports seriously and will follow up directly.